turnipsecurity.blogspot.com
turnipsecurity
http://turnipsecurity.blogspot.com/2006/03/i-have-been-tracking-since-early-last.html
Thursday, March 30, 2006. I have been tracking since early last week a large amount of web hosts that have been compromised by some web worm. I don't have the details of the worm but I do have a list of machines that have been compromised since the 24th March. Most are running one of the following;. The file that was being targeted was a perl script DDoS tool that had been recovered from the compromised host. Use IO: Socket;. My $host = ' www.ecs.soton.ac.uk. My $path = '/ cet/';. My $dst port = '80';.
turnipsecurity.blogspot.com
turnipsecurity: February 2006
http://turnipsecurity.blogspot.com/2006_02_01_archive.html
Saturday, February 25, 2006. This morning saw a new turn in the Linux worm, a new script is being distributed via; 219.84.105.36/supina. This uses a pre compiled binary backdoor, a perl backdoor and also a scanning engine (which is compiled). The scanning engine is called httpd as in previous versions;. Report on httpd -* * * * * * * * * * * * * * * * * * * * * *. BitDefender: Worm.Linux.Mare.B. ClamAV: No Virus Found. F-Prot: No Virus Found. Posted by Chas Tomlin at 8:47 AM. Windows Image Using Linux.
turnipsecurity.blogspot.com
turnipsecurity: March 2006
http://turnipsecurity.blogspot.com/2006_03_01_archive.html
Thursday, March 30, 2006. I have been tracking since early last week a large amount of web hosts that have been compromised by some web worm. I don't have the details of the worm but I do have a list of machines that have been compromised since the 24th March. Most are running one of the following;. The file that was being targeted was a perl script DDoS tool that had been recovered from the compromised host. Use IO: Socket;. My $host = ' www.ecs.soton.ac.uk. My $path = '/ cet/';. My $dst port = '80';.
turnipsecurity.blogspot.com
turnipsecurity
http://turnipsecurity.blogspot.com/2006/02/first-post-this-morning-saw-new-turn.html
Saturday, February 25, 2006. This morning saw a new turn in the Linux worm, a new script is being distributed via; 219.84.105.36/supina. This uses a pre compiled binary backdoor, a perl backdoor and also a scanning engine (which is compiled). The scanning engine is called httpd as in previous versions;. Report on httpd -* * * * * * * * * * * * * * * * * * * * * *. BitDefender: Worm.Linux.Mare.B. ClamAV: No Virus Found. F-Prot: No Virus Found. Posted by Chas Tomlin at 8:47 AM. Windows Image Using Linux.
turnipsecurity.blogspot.com
turnipsecurity
http://turnipsecurity.blogspot.com/2006/03/last-night-i-watched-lance-jamess.html
Wednesday, March 22, 2006. Last night I watched Lance James's excellent presentation Trojans and Botnets and Malware, Oh My! During the presentation I learned of a sandnet tool called truman being distributed for free by lurhq.com, so I downloaded the tools, when I unpacked the PXE client to my surprise the software looked very familiar. It was my PXE Windows Image Using Linux. Client that I build and distribute. Joe Stewart, GCIH. LURHQ http:/ www.lurhq.com/. Http:/ www.lurhq.com/truman.